CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2026-50149 MEDIUM
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
CVSS 6.5 EPSS 0.18% Aug 19, 2026
Go
CVE-2026-41246 HIGH
Contour: Lua code injection via Cookie Path Rewrite Policy
CVSS 8.1 EPSS 0.83% Apr 23, 2026
Go
CVE-2024-36539 CRITICAL
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
CVSS 9.8 EPSS 1.26% Jul 24, 2024
CVE-2023-44487 KEV MEDIUM
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
CVSS 6.9 EPSS 100.00% Oct 10, 2023
GoMavenSwiftURL
CVE-2021-32783 HIGH
Authorization bypass in Contour
CVSS 8.5 EPSS 1.15% Jul 23, 2021
Go
CVE-2020-15127 HIGH
Denial of service in Contour
CVSS 7.5 EPSS 1.38% Aug 5, 2020
Showing 1 to 6 CVEs · page 1